Privacy Policy
Last updated: July 2026
The controller within the meaning of the Swiss Federal Act on Data Protection (FADP) and – where applicable – the EU General Data Protection Regulation (GDPR) is:
SimplyConnect GmbH
Schulstrasse 2b
5426 Lengnau, Switzerland
E-mail: datenschutz@simplyconnect.ch
Website: https://simplyconnect.ch/
For all questions regarding data protection and to exercise your rights, you can reach us at the address above or by e-mail at datenschutz@simplyconnect.ch. We have not appointed a statutory data protection officer; your requests are handled directly by the controller.
General note
Based on Article 13 of the Swiss Federal Constitution and the data protection provisions of the Confederation (Federal Act on Data Protection, FADP), everyone is entitled to protection of their privacy and to protection against the misuse of their personal data. We take the protection of your personal data very seriously and treat your personal data confidentially and in accordance with the statutory provisions and this privacy policy.
In cooperation with our hosting providers, we endeavour to protect our systems as well as possible against unauthorised access, loss, misuse or falsification. However, we point out that data transmission over the internet (e.g. when communicating by e-mail) can have security vulnerabilities; complete protection of data against access by third parties is not possible.
This website can generally be visited without registration. In doing so, data such as the pages accessed or the names of retrieved files, the date and the time are stored on the server for statistical and security-related purposes. Personal data, in particular name, address or e-mail address, is collected on a voluntary basis where possible. Without your consent or a legal basis, we do not pass this data on to third parties.
The data collected when visiting this website, when using the login (e.g. accounting, FSAS.app) of SimplyConnect GmbH, when using the apps of SimplyConnect GmbH and when using the online services offered (hereinafter «online services») is processed by SimplyConnect GmbH («SimplyConnect», «simplyconnect.ch», «we» or «us») in its capacity as operator of this website and as service provider. The aforementioned offerings are hereinafter referred to as the «digital presence». Further information about SimplyConnect GmbH can be found under «About us».
Processing of personal data
Personal data is any information relating to an identified or identifiable person. A data subject is a person about whom personal data is processed. Processing covers any handling of personal data, regardless of the means and procedures applied, in particular the retention, disclosure, obtaining, deletion, storage, modification, destruction and use of personal data.
As a Swiss company, we process personal data primarily in accordance with Swiss data protection law (FADP). The FADP does not require any special justification for private controllers, provided that the processing is proportionate, transparent and carried out in good faith and that the data is obtained for a recognisable purpose. Insofar as the EU GDPR additionally applies, we base the processing on the following legal grounds in connection with Art. 6(1) GDPR:
- Consent (Art. 6(1)(a) GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual requests (Art. 6(1)(b) GDPR) – Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6(1)(c) GDPR) – Processing is necessary for compliance with a legal obligation to which we are subject.
- Legitimate interests (Art. 6(1)(f) GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
We process personal data for as long as is necessary for the respective purpose. Where longer retention obligations apply on the basis of legal or other duties to which we are subject, we restrict the processing accordingly.
We process information about our customers that is provided to us verbally, in writing or electronically, publicly available data and data we obtain from third parties, also for marketing purposes. This serves your individual advice, the delivery of offers for products and services and the improvement of our services. You may object to the use of your personal data for marketing purposes at any time (datenschutz@simplyconnect.ch).
Applicable legal bases
Insofar as the GDPR applies, we inform you of the legal bases of our data processing in accordance with Art. 13 GDPR. If the legal basis is not stated in this privacy policy, the following applies: the legal basis for obtaining consent is Art. 6(1)(a) and Art. 7 GDPR; the legal basis for processing to perform our services and carry out contractual measures as well as to respond to enquiries is Art. 6(1)(b) GDPR; the legal basis for processing to fulfil our legal obligations is Art. 6(1)(c) GDPR; and the legal basis for processing to safeguard our legitimate interests is Art. 6(1)(f) GDPR.
Security measures
In accordance with the statutory requirements and taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling access to the data as well as the access, input, disclosure, availability and separation relating to it. Furthermore, we have established procedures to ensure the exercise of data subject rights, the deletion of data and responses to threats to the data. We also take the protection of personal data into account as early as the development or selection of hardware, software and procedures, in accordance with the principle of data protection by design and by default.
Transmission of personal data
In the course of our processing of personal data, it may happen that the data is transmitted to, or disclosed to, other bodies, companies, legally independent organisational units or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content. In such cases, we observe the statutory requirements and, in particular, conclude corresponding contracts or agreements that serve to protect your data with the recipients of your data.
Data processing in third countries
Insofar as we process data in a third country (i.e. outside Switzerland, the European Union (EU) or the European Economic Area (EEA)), or the processing takes place in the context of using third-party services or the disclosure or transmission of data to third parties, this is done only in accordance with the statutory requirements.
Subject to explicit consent or contractually or legally required transmission, we process data in third countries only where there is a recognised adequate level of data protection (e.g. an adequacy recognition such as the Data Privacy Framework for certified US companies), where a contractual obligation exists through the European Commission's Standard Contractual Clauses (together with the Swiss addendum), or where other legally permissible guarantees exist.
Cookies
This website uses only technically necessary cookies or comparable technologies (e.g. for language selection, login/session status and security). Cookies are small text files stored by your browser on your device.
We do not use analytics, tracking, advertising or profiling cookies and do not pass on any cookie data for marketing or reach-measurement purposes to third parties. A distinction is made between temporary cookies (session cookies), which are deleted at the latest when you close your browser, and persistent cookies, which remain stored beyond that (e.g. for language selection).
In accordance with Art. 45c let. b of the Swiss Telecommunications Act (FMG), we inform you about the use of cookies. You can restrict or disable the storage of cookies at any time via your browser settings; if necessary cookies are disabled, the functionality of the digital presence may be limited. Insofar as the GDPR applies, technically necessary cookies are used on the basis of our legitimate interests in secure and functional operation or to perform the contract (Art. 6(1)(f) or (b) GDPR).
SSL/TLS encryption
For security reasons and to protect the transmission of confidential content, this website uses SSL/TLS encryption. You can recognise an encrypted connection by the browser address bar changing from «http://» to «https://» and by the lock symbol in your browser bar. When encryption is active, the data you transmit to us cannot be read by third parties.
Server log files
The provider of this website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- browser type and browser version
- operating system used
- referrer URL
- host name of the accessing computer
- IP address
- time of the server request
This data – in particular the IP address – may under certain circumstances allow a person to be identified. We do not merge this data with other data sources. The processing serves to ensure trouble-free and secure operation (legitimate interest); we reserve the right to review this data subsequently if we become aware of concrete indications of unlawful use.
Hosting and infrastructure
We operate our digital presence on servers in Switzerland and the European Union. As processors, we use in particular:
- hosttech GmbH, Switzerland – servers and virtual machines with data storage in Switzerland.
- Hetzner Online GmbH, Germany – virtual machines with data centres in the EU/EEA.
These providers process personal data (in particular server log data and IP addresses) exclusively to provide, securely operate and maintain our services and in accordance with our instructions. No transfer to countries without an adequate level of data protection takes place in this context.
Cloudflare
To secure and accelerate the delivery of our digital presence and for DNS and proxy services, we use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). In doing so, Cloudflare processes connection data, in particular the IP address and request metadata, in order to defend against attacks (e.g. DDoS), prevent misuse and spam, and ensure the availability and speed of our offering.
The processing is based on our legitimate interest in secure and high-performance operation (where applicable, Art. 6(1)(f) GDPR). Cloudflare is certified under the Swiss-US and EU-US Data Privacy Framework (DPF); Switzerland has recognised an adequate level of data protection for DPF-certified US companies since 15 September 2024. Further information can be found in Cloudflare's privacy policy.
AI services
For individual functions (e.g. document and invoice processing or automation), we use artificial intelligence services. We operate these on our own infrastructure (on-premise) in Switzerland and at Infomaniak Network SA (Geneva, Switzerland).
Any personal data arising is processed exclusively in Switzerland or the EU/EEA and is not used to train publicly available third-party AI models. Insofar as we use AI to support decisions, no decision based solely on automated processing with legal effect or a similarly significant adverse impact within the meaning of Art. 21 FADP is made without a natural person reviewing the results.
Microsoft 365 and video conferences
For e-mail communication, office applications and the holding of audio and video conferences or online meetings (in particular via Microsoft Teams), we use Microsoft 365 provided by Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland).
Contact, communication and usage data of participants may be processed. We use these services to perform contractual obligations and on the basis of our legitimate interests in efficient and secure communication (where applicable, Art. 6(1)(b) and (f) GDPR). Microsoft is certified under the Swiss-US and EU-US Data Privacy Framework and, with the «EU Data Boundary», offers the processing of customer data within the EU/EEA. Further information can be found in Microsoft's privacy statement.
Contacting us
If you contact us by e-mail, telephone or – where offered – via a form, your details, including the contact data you provide, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass this data on without your consent and delete it as soon as it is no longer required for the purpose and no statutory retention obligations preclude deletion.
Newsletter
If you wish to receive the newsletter offered on this website, we require your e-mail address as well as information that allows us to verify that you are the owner of the e-mail address provided and that you agree to receive the newsletter (double opt-in). No further data is collected.
Dispatch takes place via our own, internally operated infrastructure; we do not use any external newsletter service provider and do not pass your data on to third parties. You can revoke your consent to the storage of your e-mail address and its use for sending the newsletter at any time, for example via the «unsubscribe» link in the newsletter.
Rights of data subjects
Under the applicable data protection law, you have in particular the following rights. To exercise them, an informal message to datenschutz@simplyconnect.ch is sufficient. Under Swiss law, we generally answer access requests within 30 days and usually free of charge.
Right of access
You have the right to request confirmation as to whether personal data concerning you is being processed, and to receive free information about the data stored about you and a copy of this data. In addition, information may be provided about the following:
- the processing purposes
- the categories of personal data processed
- the recipients or categories of recipients to whom the data is disclosed
- the planned storage period or the criteria for determining it
- the existence of a right to rectification, erasure or restriction of processing and of a right to object
- the existence of a right to lodge a complaint with the supervisory authority
- where the data was not collected from you: the available information about the origin of the data
- in the case of transfer abroad: the country concerned and the appropriate safeguards
Right to rectification
You have the right to request the immediate rectification of inaccurate personal data concerning you and the completion of incomplete personal data.
Right to erasure
You have the right to request the erasure of personal data concerning you, provided that the processing is not necessary – in particular where the data is no longer needed for the purposes pursued, you withdraw consent and there is no other legal basis, you legitimately object, or the data was processed unlawfully. Statutory retention obligations remain reserved.
Right to restriction of processing
You have the right to request the restriction of processing, for example if you contest the accuracy of the data, the processing is unlawful, we no longer need the data but you require it to assert legal claims, or you have objected.
Right to data portability / data disclosure
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format or – where technically feasible – to request its transmission to another controller.
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you. You may object to processing for direct marketing purposes at any time.
Right to withdraw consent
If you have consented to processing, you can withdraw this consent at any time with effect for the future.
Right to lodge a complaint with the supervisory authority
Without prejudice to other legal remedies, you have the right to lodge a complaint with the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC, https://www.edoeb.admin.ch). Insofar as the GDPR applies, you may also contact the data protection supervisory authority responsible for you.
Objection to advertising e-mails
We hereby object to the use of contact data published in the context of the imprint obligation for sending advertising and information material that has not been expressly requested. We expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example by spam e-mails.
Chargeable services
To provide chargeable services, we request additional data, such as payment details, in order to be able to carry out your order or assignment. We store this data in our systems until the statutory retention periods have expired.
External payment service providers
For the processing of payments, we use external payment service providers via whose platforms the payment transactions are carried out:
In the context of contract performance, we use the payment service providers on the basis of Swiss data protection law and, where necessary, Art. 6(1)(b) GDPR; otherwise on the basis of our legitimate interests in secure and efficient payment processing (Art. 6(1)(f) GDPR). The data processed includes master data (e.g. name and address), payment data and contract- and amount-related information. The payment means data is processed and stored exclusively by the payment service providers; we ourselves receive no complete account or credit card data, only a confirmation or rejection of the payment. The terms and conditions and privacy notices of the respective payment service providers apply in addition.
Contractual services
We process the data of our contractual and business partners, e.g. customers and prospects (collectively «contractual partners»), in the context of contractual and comparable legal relationships and associated measures, and in the context of communication with the contractual partners (or pre-contractually), e.g. to answer enquiries.
We process this data to fulfil our contractual obligations, to safeguard our rights and for the purposes of the associated administrative tasks and business organisation. We pass on the data of contractual partners to third parties within the framework of applicable law only insofar as this is necessary for the aforementioned purposes or to fulfil legal obligations, or occurs with the consent of the data subjects (e.g. to transport and other auxiliary services involved, subcontractors, banks, tax and legal advisers, payment service providers or tax authorities).
We inform contractual partners of which data is required for the aforementioned purposes before or in the course of data collection. We delete the data after expiry of statutory warranty and comparable obligations, i.e. generally after 4 years, unless the data must be retained longer for statutory archiving reasons (e.g. generally 10 years for tax purposes).
Customer account: Contractual partners can create an account within our online offering. Customer accounts are not public and cannot be indexed by search engines. As part of registration and subsequent logins and use of the customer account, we store the customers' IP addresses together with the access times in order to be able to prove the registration and prevent any misuse. If customers have terminated their customer account, the data relating to the customer account will be deleted, subject to any legally required retention.
Analyses and market research: For business reasons and in order to identify market trends and the wishes of contractual partners and users, we analyse the data available to us on business transactions, contracts and enquiries. The analyses serve us alone and are not disclosed externally, unless they are anonymous analyses with aggregated values. We process the data for analysis purposes in as pseudonymous a form as possible and, where feasible, anonymously.
Agency services: We process our customers' data in the context of our contractual services, which may include, for example, conceptual and strategic advice, software and design development/consulting or maintenance, the implementation of processes, server administration, data analysis and training services.
Administration, financial accounting, office organisation
We process data in accordance with the data protection provisions of the Confederation (FADP) and – where applicable – the GDPR in the context of administrative tasks, the organisation of our operations, financial accounting and compliance with legal obligations (e.g. archiving). Customers, prospects, business partners and website visitors are affected by this processing.
For invoicing and accounting, we use the Swiss accounting software Abaninja (Swiss21 platform of Abacus Research AG, Abacus-Platz 1, 9300 Wittenbach); the data is hosted in Switzerland. In particular, customer and invoice data (name, address and service- and amount-related information) is processed. In addition, we disclose or transmit data to the tax administration, to advisers (e.g. tax advisers or auditors) and to other charging bodies and payment service providers.
Note on data processing in the USA
Some of the services we use (in particular Cloudflare and Microsoft) are provided by companies based in the USA, whereby the processing of personal data in the USA cannot be ruled out. These companies are certified under the Swiss-US and EU-US Data Privacy Framework (DPF); Switzerland and the EU recognise an adequate level of data protection for DPF-certified US companies (for Switzerland since 15 September 2024). Insofar as a recipient is not certified, we base a transfer on the European Commission's Standard Contractual Clauses together with the Swiss addendum, or on another legally permissible guarantee.
Copyright
The copyright and all other rights to content, images, photos or other files on the website belong exclusively to SimplyConnect GmbH or to the specifically named rights holders. The written consent of the copyright holder must be obtained in advance for the reproduction of any files. Anyone who commits a copyright infringement without the consent of the respective rights holder may be liable to prosecution and possibly to damages.
General disclaimer
All information in our internet offering has been carefully checked. We endeavour to keep our information offering up to date, correct and complete. Nevertheless, the occurrence of errors cannot be completely ruled out, so that we cannot assume any guarantee for the completeness, accuracy and timeliness of information. Liability claims for damage of a material or immaterial nature caused by the use of the information provided are excluded, unless there is demonstrably wilful or grossly negligent fault.
We also assume no responsibility or liability for the content and availability of third-party websites that can be reached via external links. The operators of the linked pages are solely responsible for their content.
Changes
We may amend this privacy policy at any time without prior notice. The version currently published on our website applies. Insofar as the privacy policy is part of an agreement with you, we will inform you of any update by e-mail or by other suitable means.
Questions about data protection
If you have any questions about data protection, please write to us at datenschutz@simplyconnect.ch or contact the controller named at the beginning of this privacy policy.